Show filters
16,626 Total Results
Displaying 341-350 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2025-0680
Disclosure Date: January 30, 2025 (last updated February 27, 2025)
Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.
0
Attacker Value
Unknown
CVE-2025-22222
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.
0
Attacker Value
Unknown
CVE-2025-22221
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
0
Attacker Value
Unknown
CVE-2025-22220
Disclosure Date: January 30, 2025 (last updated February 27, 2025)
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.
0
Attacker Value
Unknown
CVE-2025-22219
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.
0
Attacker Value
Unknown
CVE-2025-22218
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
0
Attacker Value
Unknown
CVE-2024-13484
Disclosure Date: January 28, 2025 (last updated February 27, 2025)
A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.
0
Attacker Value
Unknown
CVE-2024-8401
Disclosure Date: January 28, 2025 (last updated February 27, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
vulnerability exists when an authenticated attacker modifies folder names within the context of
the product.
0
Attacker Value
Unknown
CVE-2025-0754
Disclosure Date: January 28, 2025 (last updated February 27, 2025)
The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log injection and spoofing attacks. Such injections can mislead logging mechanisms, enabling attackers to manipulate log entries or execute reflected cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2025-0752
Disclosure Date: January 28, 2025 (last updated February 27, 2025)
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.
0